
oss-oopssec-store v2.18.0
Sicherheitstraining für die Apps, die Sie tatsächlich ausliefern. Öffnen Sie Ihren Browser und beginnen Sie zu hacken.
OSS - OopsSec Store
Sicherheitstraining für die Apps, die du tatsächlich auslieferst.
36 Challenges aus den Bereichen Web, API, Authentifizierung, Business-Logik, Kryptografie, Supply Chain, KI-Agenten und MCP.
Knacke eine absichtlich verwundbare E-Commerce-App, die auf Next.js, React, TypeScript und Prisma basiert.
Finde die Bugs. Nutze sie aus. Verstehe, warum sie funktionieren.
Docker Hub · npm · Roadmap · Walkthroughs · Contributing · Good first issues
/ __ / // / / __ \ ___ ___ ___ / / ___ ____ / / / / ___ ____ ___ / // /\ \ \ \ / // // _ \ / _ (-<\ \ / -)/ __/\ \ / // _ \ / // -) _//// __/ _// ./// _/ _/// _/ ___/// _/ /_/
Start with Node.js
npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start
Start with Docker
docker run -p 127.0.0.1:3000:3000 leogra/oss-oopssec-store
Then open http://localhost:3000 and start hacking
<div align="center">
<table>
<tr>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-0.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-0.png" alt="OopsSec Store storefront" width="100%"></a>
<br><sub><b>Storefront</b> · die E-Commerce-App, die du angreifst</sub>
</td>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-1.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-1.png" alt="Player dashboard tracking captured flags" width="100%"></a>
<br><sub><b>Player-Dashboard</b> · Fortschritt, Schwierigkeit und Kategorie-Aufschlüsselung</sub>
</td>
</tr>
<tr>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-2.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-2.png" alt="OSSBot AI customer support assistant" width="100%"></a>
<br><sub><b>OSSBot</b> · der KI-Support-Assistent, den du per Prompt-Injection angreifst</sub>
</td>
<td width="50%" align="center">
<a href="https://github.com/koadt/oss-oopssec-store/blob/main/public/oopssec-store-storefront-3.png"><img src="https://raw.githubusercontent.com/koadt/oss-oopssec-store/main/public/oopssec-store-storefront-3.png" alt="Challenge roadmap across 11 chapters" width="100%"></a>
<br><sub><b>Roadmap</b> · die Bugs, die in Produktionscode landen</sub>
</td>
</tr>
</table>
<sub>Klicke auf einen Screenshot, um ihn in voller Größe anzuzeigen.</sub>
</div>
---
## Erste Schritte
<table>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/1-15803d?style=for-the-badge" alt="Step 1"></td>
<td valign="top">
<b>Starte das Lab</b><br>
<code>npx create-oss-store my-ctf-lab && cd my-ctf-lab && npm start</code><br>
<sub>Oder <a href="#docker">führe es mit Docker aus</a>. Der Store startet auf <a href="http://localhost:3000">localhost:3000</a>.</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/2-15803d?style=for-the-badge" alt="Step 2"></td>
<td valign="top">
<b>Nimm Challenge #1 ins Visier</b><br>
<a href="http://localhost:3000/vulnerabilities/public-env-variable">Public env variable leak</a>: ein Zahlungsgeheimnis, das Next.js in das Client-Bundle einbaut.<br>
<sub>Einfach · 15–20 Min · nichts außer deinen Browser-Devtools.</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/3-15803d?style=for-the-badge" alt="Step 3"></td>
<td valign="top">
<b>Festgefahren? Lies die Walkthrough</b><br>
Jede Challenge hat eine, von der Schwachstelle über den Exploit bis zum Fix.<br>
<sub>Die erste: <a href="https://koadt.github.io/oss-oopssec-store/posts/next-public-env-variable-leak/">Reading Secrets From the Browser: The NEXT_PUBLIC_ Trap in Next.js</a>.</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/4-15803d?style=for-the-badge" alt="Step 4"></td>
<td valign="top">
<b>Validiere die Flag</b><br>
Füge <code>OSS{...}</code> in den Flag-Checker ein, das schwebende Widget auf jeder Seite.<br>
<sub>Dein <a href="http://localhost:3000/player-dashboard">Player-Dashboard</a> verfolgt, was noch übrig ist.</sub>
</td>
</tr>
<tr>
<td width="56" align="center" valign="top"><img src="https://img.shields.io/badge/5-15803d?style=for-the-badge" alt="Step 5"></td>
<td valign="top">
<b>Wähle die nächste</b><br>
Die <a href="https://koadt.github.io/oss-oopssec-store/roadmap">Roadmap</a> ordnet jede Challenge über Kapitel hinweg: Schwierigkeit, Zeitaufwand, Voraussetzungen.<br>
<sub>Nimm die nächste Karte, dann zurück zu Schritt 2. ↻</sub>
</td>
</tr>
</table>
> [!TIP]
> Alles erobert? [Tritt der Hall of Fame bei](#hall-of-fame), starre das Repo und poste deine Route in [Show your solve](https://github.com/kOaDT/oss-oopssec-store/discussions/categories/show-your-solve).
<sub>Neu in der Offensive Security? Der <a href="https://tryhackme.com/jr/oopssecstorethesummeraudit">TryHackMe-Raum</a> verpackt die ersten Flags in eine geführte Erzählung.</sub>
---
## Inhaltsverzeichnis
- [Features](#features)
- [Warum OopsSec Store?](#why-oopssec-store)
- [Installation](#installation)
- [Schnellstart (npm)](#quick-start)
- [Docker](#docker)
- [Hall of Fame](#hall-of-fame)
- [Community](#community)
- [Projektstruktur](#project-structure)
- [Testing](#testing)
- [Haftungsausschluss](#disclaimer)
- [Mitwirken](#contributing)
- [Educator Kit](#-using-oopssec-store-in-a-course-or-ctf)
- [Projektstatistiken](#project-stats)
---
> [!WARNING]
> Diese Anwendung enthält absichtliche Sicherheitslücken und darf niemals in einer Produktionsumgebung bereitgestellt werden.
## Features